Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2900 | Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be executed on the victims’ (other users including admins) browsers. This issue is fixed in 2.6.5. |
Github GHSA |
GHSA-255w-87rh-rg44 | Cross-site Scripting via uploaded SVG |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sulu
Sulu sulu |
|
| CPEs | cpe:2.3:a:sulu:sulu:*:*:*:*:*:*:*:* cpe:2.3:a:sulu:sulu:2.0.0:-:*:*:*:*:*:* cpe:2.3:a:sulu:sulu:2.0.0:rc1:*:*:*:*:*:* cpe:2.3:a:sulu:sulu:2.0.0:rc2:*:*:*:*:*:* cpe:2.3:a:sulu:sulu:2.0.0:rc3:*:*:*:*:*:* |
|
| Vendors & Products |
Sulu
Sulu sulu |
|
| Metrics |
cvssV3_1
|
Tue, 08 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be executed on the victims’ (other users including admins) browsers. This issue is fixed in 2.6.5. | |
| Title | Sulu vulnerable to XSS via uploaded SVG | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-18T14:42:45.592Z
Reserved: 2024-09-27T20:37:22.121Z
Link: CVE-2024-47618
Updated: 2024-10-08T13:34:04.336Z
Status : Analyzed
Published: 2024-10-03T15:15:15.147
Modified: 2024-10-08T14:31:08.180
Link: CVE-2024-47618
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA